CVE-2025-48061

wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logged in again after re-opening the application. This does not happen when the user is logged in as a temporary user by selecting "This is a public computer" during login or the user selects "Delete all your personal information and conversations on this device" upon logout. The underlying issue has been fixed with wire-webapp version 2025-05-20-production.0. As a workaround, this behavior can be prevented by either deleting all information upon logout as well as logging in as a temporary client.
Configurations

No configuration.

History

23 May 2025, 15:55

Type Values Removed Values Added
Summary
  • (es) wire-webapp es la aplicación web para el servicio de mensajería de código abierto Wire. Un cambio provocó una regresión que impidió que las sesiones se invalidaran correctamente. Un usuario que cerraba sesión en la aplicación web de Wire podría haber vuelto a iniciar sesión automáticamente al reabrirla. Esto no ocurre cuando el usuario inicia sesión como usuario temporal seleccionando "Este es un equipo público" al iniciar sesión o seleccionando "Eliminar toda su información personal y conversaciones en este dispositivo" al cerrar sesión. El problema subyacente se ha solucionado con la versión 2025-05-20-production.0 de wire-webapp. Como workaround, este comportamiento se puede evitar eliminando toda la información al cerrar sesión o iniciando sesión como cliente temporal.

22 May 2025, 18:15

Type Values Removed Values Added
Summary (en) wire-webapp is the web application for the open-source messaging service Wire. A change introduced in version 2025-05-14-production.0 caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logged in again after re-opening the application. This does not happen when the user is logged in as a temporary user by selecting "This is a public computer" during login or the user selects "Delete all your personal information and conversations on this device" upon logout. The underlying issue has been fixed with wire-webapp version 2025-05-20-production.0. As a workaround, this behavior can be prevented by either deleting all information upon logout as well as logging in as a temporary client. (en) wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logged in again after re-opening the application. This does not happen when the user is logged in as a temporary user by selecting "This is a public computer" during login or the user selects "Delete all your personal information and conversations on this device" upon logout. The underlying issue has been fixed with wire-webapp version 2025-05-20-production.0. As a workaround, this behavior can be prevented by either deleting all information upon logout as well as logging in as a temporary client.

22 May 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-22 17:15

Updated : 2025-05-23 15:55


NVD link : CVE-2025-48061

Mitre link : CVE-2025-48061

CVE.ORG link : CVE-2025-48061


JSON object : View

Products Affected

No product.

CWE
CWE-613

Insufficient Session Expiration